User-Centric Authentication for Connected Vehicle Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Connected devices, such as vehicles, face challenges with static pairings that lead to loss of functionality when users replace devices more frequently than vehicles, resulting in multiple subscriptions and memory/processor resource wastage due to OEM-specific applications for accessing services like remote-start or streaming services.
Innovation Solution
An authentication server communicates with user devices to authenticate access to vehicle services, generating security keys for secure elements, enabling single-app operation across multiple vehicles and reducing subscription needs by linking user profiles and providing biometric authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static pairing is used between connected devices and vehicles, then initial authentication is simplified, but functionality is lost when users replace devices frequently
Solution Approach 1:
The patent implements dynamic pairing where authentication credentials are not statically bound to specific devices but are instead associated with user accounts. When a device is replaced, the new device can be authenticated by linking it to the user's account, allowing the system to adapt to device changes while maintaining secure access. This resolves the contradiction by making the pairing relationship flexible rather than fixed.
Solution Approach 2:
The authentication system is designed to work across multiple device types and platforms universally. Instead of requiring device-specific static pairing, the system uses a universal user account-based authentication mechanism that works with smartphones, tablets, wearables, and other connected devices. This allows users to replace devices without losing functionality, as the authentication is tied to the user rather than the specific device.
2Reliability
If OEM-specific applications are installed for each vehicle service, then access control is maintained, but memory and processor resources are wasted
Solution Approach 1:
The patent merges multiple OEM-specific authentication functions into a single unified authentication application. Instead of requiring separate applications for each vehicle service, the system combines authentication, authorization, and service access control into one integrated application. This reduces the quantity of software resources while maintaining reliable access control through centralized authentication mechanisms.
Solution Approach 2:
The authentication application is designed as a universal multi-functional solution that can access multiple vehicle services through a single interface. Rather than requiring separate dedicated applications for each service, the universal application handles various authentication scenarios (vehicle access, remote start, diagnostics, etc.) through a common authentication framework, thereby reducing memory and processor utilization while maintaining security.
3Reliability
If multiple subscriptions are required for different vehicle services, then service access is controlled, but subscription management complexity increases
Solution Approach 1:
The system merges multiple service subscriptions and access rights into a unified user profile. Instead of managing separate subscriptions for different vehicle services, the authentication application consolidates all service access rights, subscription statuses, and authorization levels into a single user account. This reduces subscription management complexity while maintaining controlled access to various vehicle services through centralized credential verification.
Data Source
AI summary
In some implementations, an authentication system may receive a user authentication request identifying a primary device. The authentication system may generate a challenge associated with a user profile mapped to the primary device. The authentication system may transmit a challenge message including the challenge. The authentication system may receive a challenge response including a response to the challenge, wherein the response to the challenge includes identification information regarding the user profile. The authentication system may determine a set of primary services associated with the user profile mapped to the primary device and a set of secondary services associated with a set of secondary devices. The authentication system may generate a set of security keys mapped to the set of primary services and the set of secondary services. The authentication system may provision the primary device and the set of secondary devices with the set of security keys.


